{"id":"CVE-2021-23408","details":"This affects the package com.graphhopper:graphhopper-web-bundle before 3.2, from 4.0-pre1 and before 4.0. The URL parser could be tricked into adding or modifying properties of Object.prototype using a constructor or __proto__ payload.","aliases":["GHSA-qhxh-9hhx-6p7v"],"modified":"2026-02-20T16:41:25.201473Z","published":"2021-07-21T16:15:08.613Z","related":["SNYK-JAVA-COMGRAPHHOPPER-1320114"],"references":[{"type":"ADVISORY","url":"https://github.com/graphhopper/graphhopper/pull/2370"},{"type":"ADVISORY","url":"https://github.com/graphhopper/graphhopper/releases/tag/3.1"},{"type":"ADVISORY","url":"https://github.com/graphhopper/graphhopper/releases/tag/3.2"},{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-JAVA-COMGRAPHHOPPER-1320114"},{"type":"FIX","url":"https://github.com/graphhopper/graphhopper/pull/2370"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JAVA-COMGRAPHHOPPER-1320114"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/graphhopper/graphhopper","events":[{"introduced":"0"},{"fixed":"3de45343ed6d3a413a7fe4ca57daea49a25caedb"},{"introduced":"0"},{"fixed":"784470f3315717abe4920435f24e9d08dae63267"}]}],"versions":["0.10.0","0.10.0-RC1","0.10.alpha1","0.10.alpha3","0.10.alpha4","0.10.alpha5","0.10.alpha6","0.10.alpha7","0.11.0","0.11.0-pre1","0.11.0-pre2","0.11.0-pre3","0.11.0-pre4","0.11.0-pre5","0.11.0-pre6","0.12.0-pre","0.12.0-pre1","0.12.0-pre2","0.12.0-pre3","0.12.0-pre5","0.12.0-pre6","0.13.0","0.13.0-pre1","0.13.0-pre10","0.13.0-pre11","0.13.0-pre12","0.13.0-pre13","0.13.0-pre14","0.13.0-pre16","0.13.0-pre17","0.13.0-pre18","0.13.0-pre19","0.13.0-pre2","0.13.0-pre3","0.13.0-pre4","0.13.0-pre5","0.13.0-pre6","0.13.0-pre7","0.13.0-pre8","0.13.0-pre9","0.14.0-pre1","1.0","1.0-pre1","1.0-pre10","1.0-pre11","1.0-pre12","1.0-pre13","1.0-pre14","1.0-pre15","1.0-pre16","1.0-pre17","1.0-pre18","1.0-pre19","1.0-pre2","1.0-pre20","1.0-pre21","1.0-pre22","1.0-pre23","1.0-pre24","1.0-pre25","1.0-pre26","1.0-pre27","1.0-pre28","1.0-pre29","1.0-pre3","1.0-pre30","1.0-pre31","1.0-pre32","1.0-pre33","1.0-pre33.2","1.0-pre33.3","1.0-pre33.4","1.0-pre34","1.0-pre35","1.0-pre36","1.0-pre37","1.0-pre38","1.0-pre39","1.0-pre4","1.0-pre40","1.0-pre41","1.0-pre42","1.0-pre43","1.0-pre5","1.0-pre6","1.0-pre7","1.0-pre7.1","1.0-pre8","1.0-pre9","2.0","2.0-pre1","2.0-pre2","2.0-pre3","3.0","3.0-pre1","3.0-pre2","3.0-pre3","3.0-pre4","3.0-pre5","3.1","stable"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-23408.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"}]}